Jaded Security

INDUSTRY · 2011-06-04Why I Lost All Respect for ISC2

– Boris Sverdlik

An editorial piece by Jaded Security on the failure of ISC2 to respond to the operational realities the LulzSec and AntiSec campaigns exposed in 2011.

For years the CISSP has been defended in arguments with people who call it worthless. The argument that the certification provides a solid baseline of knowledge is the conventional one inside the security industry, repeated by everyone who has held the credential and used it to get hired.

That argument has run out.

The breaking point

ISC2 has become everything that is wrong with the security industry wrapped up in a nice non-profit package. Obscene fees for a certification that tests the ability to memorise a study guide. Continuing education turned into a revenue stream. Governance structured so that the membership cannot meaningfully hold the board accountable.

What finally tips the balance is the response, or rather the complete lack of response, to the current wave of attacks. While LulzSec embarrassed organisation after organisation using techniques that any CISSP holder should be able to defend against, ISC2 was busy running another certification program. Another revenue stream. Another set of fees.

The certification industrial complex

Here is what ISC2 will never admit: the CISSP exam does not prepare candidates to defend against real attacks. It prepares them to pass the CISSP exam. Those are not the same thing.

The industry is full of CISSP holders who cannot configure a firewall. CISSP holders who have never looked at a packet capture. CISSP holders whose entire security career consists of writing policies that nobody reads and filling out compliance checklists that prove nothing.

ISC2 is fine with this. Because those people pay annual maintenance fees.

What the CISSP actually tests

The CISSP tests memorisation of the ISC2 Common Body of Knowledge — a document that, by the time it is published, is already several years behind the current threat landscape. Access-control models from the 1970s. Security-governance frameworks that exist primarily to justify their own existence. Just enough cryptography to be dangerous.

What candidates do not learn: how to actually break things, which means they do not learn how to actually defend against people who break things.

The alternative

This is not an argument that certifications are useless. It is an argument that ISC2 has lost its way. To actually learn security, go to a CTF. Set up a lab. Break things. Read the source code. Follow the researchers who are finding real vulnerabilities in real products.

The alternative is to keep paying ISC2 the annual fees and collecting the CPE credits. That will protect no organisation from the next SQL injection attack.


Jaded Security